Cloud sandboxes
The real cloud console, with guardrails for every learner.
Each learner gets their own sandbox on Azure, AWS, Google Cloud, Oracle Cloud, Databricks or Azure AI Foundry. They work in the real console. We set limits on what they can create, track spend and clean up when access ends.
Every sandbox
- Sign-in
- Own login
- Limits
- Set for the course
- Spend
- Tracked per learner
- Access ends
- On the agreed date
Providers
Pick the cloud your course is built on.
Every sandbox belongs to one learner. Choose a provider to see what the learner gets and the limits we set.
Entra ID · resource groups
Microsoft Azure
A Microsoft Entra ID sign-in and resource groups that belong to one learner.
Azure limits
- Virtual machines
- up to 3
- Load balancers
- up to 1
- Application gateways
- up to 1
What the learner gets
- Their own Microsoft Entra ID sign-in to the Azure portal
- Their own resource groups to create, change and delete resources in
- A sandbox they can relaunch after it expires, when the trainer allows it
Guardrails
- Resource limits per sandbox: up to 3 virtual machines, 1 load balancer and 1 application gateway
- Extra VMs are stopped automatically, and extra load balancers or application gateways are removed
- Azure Policy restricts which services and VM sizes can be used
- A daily hour cap and a countdown to the end of access
- The sandbox expires at the end of access and its resources are removed
Typical use
- AZ-900 practice
- AZ-104 practice
Console · tagged resources
Amazon Web Services
An AWS sandbox where every resource is traced back to the learner who created it.
AWS guardrails
- Spend
- Budget per learner
- Resources
- Tagged to the learner
What the learner gets
- Their own sign-in to the AWS Management Console
- Room to build with the AWS services the course needs
Guardrails
- Resources are tagged to the learner who created them
- A budget per learner, with alerts that track spend
- What a learner can create is limited to what the course needs
- Access ends on the agreed date and resources are removed
Typical use
- Cloud Practitioner (CLF-C02) practice
- Solutions Architect Associate (SAA-C03) practice
Project per learner
Google Cloud
A Google Cloud project per learner with resource limits, so they use the real console safely.
GCP guardrails
- Daily cap
- Hours per day, per learner
- Services
- Allowed and restricted lists
What the learner gets
- Their own Google Cloud project, opened from a login link in the portal
- Sign-in with their own Google account
- Start-here steps, the region to use and a countdown to the end of access
Guardrails
- A list of allowed services and a list of restricted services for each lab template
- A daily hour cap, with the hours left shown to the learner
- Spend is tracked for each learner’s project
- The project is removed at the end of access
Typical use
- Cloud Digital Leader practice
- Associate Cloud Engineer practice
Compartment per learner
Oracle Cloud Infrastructure
A compartment per learner, with quotas and shape limits enforced automatically.
OCI guardrails
- Session limit
- Set per template
- Daily and total caps
- Set per learner
- Out-of-policy instances
- Removed
What the learner gets
- Their own compartment in Oracle Cloud
- Their own sign-in to the OCI console
Guardrails
- Deployed from a template with allowed services (compute, storage, networking, Autonomous Database, Functions and more) and blocked ones (Exadata, bare metal, GPU instances, FastConnect, GoldenGate)
- Shape limits are enforced automatically. Instances outside the allowed shapes are removed
- A session time limit, plus daily and total hour caps per learner
- After the batch end date, the learner’s sandbox user is deleted
Typical use
- OCI Foundations Associate practice
- OCI Architect Associate practice
Workspace access
Databricks
Databricks workspace access per learner, with limits on the compute they can start.
Databricks guardrails
- Compute
- Within set limits
- Workspace access
- Own sign-in
What the learner gets
- Their own access to a Databricks workspace
- Notebooks and compute for the course exercises
Guardrails
- Limits on the compute a learner can start
- Spend is tracked for each learner
- Access is removed at the end of the batch
Typical use
- Data Engineer Associate practice
- Spark and notebooks practice
Dedicated AI resource
Azure AI Foundry
A dedicated Azure OpenAI resource per learner in Azure AI Foundry (now called Microsoft Foundry), for deploying and calling models.
AI Foundry guardrails
- AI resource
- One per learner
- Model quota
- Set per learner
What the learner gets
- Their own Azure OpenAI / AI Foundry resource
- Rights to deploy models and call them from their own code
Guardrails
- Model quota is set per learner
- Spend is tracked for each learner
- The resource is removed at the end of access
Typical use
- AI-901 practice
- AI-103 practice
- Generative AI course
Guardrails
Guardrails on every sandbox.
Learners work in the real cloud, so we set limits before the batch starts. The details differ by provider. These are the controls we use.
- Own login per learner
- Each learner signs in with their own account. Nobody shares a password, and each learner’s work stays separate.
- Limits on what can be created
- Policies and quotas set which services and sizes a learner can use. Anything outside the limits is refused or removed.
- Spend control
- Spend is tracked for each learner, not only for the batch as a whole.
- Daily and total hour caps
- Where the provider allows it, each learner gets a set number of hours per day, and optionally in total. Learners can see how much time is left.
- Automatic expiry and clean-up
- Access ends on the date you agree with us. The sandbox and the resources in it are removed.
Choosing
Sandbox or lab machine?
Three kinds of lab, for three kinds of course. If you are not sure, tell us the course and we will suggest one.
Cloud sandbox
- What the learner gets
- Their own login to the real cloud console, with limits.
- Choose it when
- Learners must practise in the console itself: networks, VMs, storage, data or AI models.
- Example
- AZ-104 practice in the Azure portal
Lab machine
- What the learner gets
- A Windows or Linux desktop in a browser tab, with your course software installed.
- Choose it when
- The course is about software, not a cloud account. For example Linux, Windows Server, databases or Kubernetes.
- Example
- Linux system administration on RHEL
Official labUp to 30% off
- What the learner gets
- The lab environment for an official Microsoft Azure or AWS course.
- Choose it when
- You deliver an official Microsoft or AWS course and need the labs that go with it.
- Example
- An official Azure administrator course
| Compare | Cloud sandbox | Lab machine | Official labUp to 30% off |
|---|---|---|---|
| What the learner gets | Their own login to the real cloud console, with limits. | A Windows or Linux desktop in a browser tab, with your course software installed. | The lab environment for an official Microsoft Azure or AWS course. |
| Choose it when | Learners must practise in the console itself: networks, VMs, storage, data or AI models. | The course is about software, not a cloud account. For example Linux, Windows Server, databases or Kubernetes. | You deliver an official Microsoft or AWS course and need the labs that go with it. |
| Example | AZ-104 practice in the Azure portal | Linux system administration on RHEL | An official Azure administrator course |
| Compare providers: Cloud sandbox | Browse lab machines: Lab machine | See official labs: Official lab |
Tell us the course. We’ll set up the sandboxes.
Share the cloud, the number of learners and the dates. We’ll come back with the limits we recommend and a written quote.
